26 Belden Ave, Norwalk, CT, U.S.A info@ecsgtech.com Mon–Fri 9am–5pm | Sat 9am–2:30pm
ECSG
Get a Demo
Help Center

Frequently Asked Questions

Clear answers about our cloud services, cybersecurity, networking, infrastructure and enterprise technology. Everything you need to know about ECSG.

9Categories
65+Questions
38+Terms

🔍 Search Answers

🔎
All M365 Azure Cyber Networking Glossary
🏢

General ECSG

Who we are, what we offer and how we work

Enterprise Cloud Solutions Group LLC (ECSG) is a Managed Service Provider (MSP) headquartered in Norwalk, Connecticut, specializing in enterprise-grade technology solutions for small and medium-sized businesses (SMBs) across the United States.

Our services include Microsoft 365, Azure Cloud, Cybersecurity, Managed IT, vCIO Consulting, Web Design, Camera Installation, Network Infrastructure and Structured Cabling.

ℹ️ Our tagline is "Secure. Reliable. Human." — representing our commitment to deliver world-class technology with personalized attention.

ECSG operates exclusively in the United States market, with headquarters in Norwalk, Connecticut. We serve SMBs (10–50 users) primarily across Fairfield County, CT and the greater New York City metro area, with the ability to support clients throughout the country through our remote-first service model.

We offer bilingual support (English and Spanish) to ensure every U.S.-based client — regardless of their team's preferred language — gets clear, reliable technology guidance.

Working with ECSG is simple and friction-free:

  1. Free assessment (48 hours): we evaluate your current infrastructure and identify critical gaps at no cost or commitment.
  2. Tailored plan: we design a technical roadmap adapted to your company, budget and goals.
  3. Migration and setup: we execute the implementation without interrupting your operations — zero-downtime migration.
  4. Continuous 24/7 support: your team has permanent technical backup, no exceptions.
✉️ To get started, email us at info@ecsgtech.com or visit www.ecsgtech.com

ECSG guarantees 99.9% uptime on managed services under an SLA (Service Level Agreement) contract. This means your infrastructure will be available virtually at all times, with contractually defined response times.

We also guarantee zero-downtime migration, 24/7 support and Spanish-language assistance for all our clients.

An SLA (Service Level Agreement) is a formal contract between ECSG and the client that defines service metrics such as availability, response times, incident resolution times and penalties for non-compliance.

ECSG's SLA guarantees 99.9% uptime — less than 9 hours of permitted downtime per year.

ECSG uses a transparent, consultative pricing model rather than one-size-fits-all packages. Your investment depends on factors such as:

  • Number of users and devices to be supported
  • Which services you need (Managed IT, Cybersecurity, Microsoft 365, Azure, vCIO, networking, cameras)
  • Your current infrastructure and the level of remediation required
  • Compliance requirements specific to your industry (HIPAA, PCI DSS, etc.)

Most Managed IT and Cybersecurity engagements are billed as a predictable monthly per-user or per-device fee, while Microsoft 365 and Azure licensing follow standard Microsoft pricing. We always start with a free, no-commitment assessment so you receive an accurate, itemized quote before any work begins.

💰 No hidden fees, no long lock-in contracts you weren't told about — every proposal is itemized and explained line by line.

Yes. ECSG is specifically designed to serve SMBs (small and medium-sized businesses) that need enterprise-grade technology without the cost of an in-house IT department. We serve companies from 5 employees up to organizations with hundreds of users.

You can reach the ECSG team through the following channels:

  • General email: info@ecsgtech.com
  • Website: www.ecsgtech.com
  • Instagram: @ecsg.usa
  • Address: 26 Belden Ave, Norwalk, CT

Clients with an active SLA contract have access to priority 24/7 technical support.

🪟

Microsoft 365

Licenses, apps, email and collaboration

Microsoft 365 for business includes a complete suite of productivity and collaboration tools:

  • Outlook: professional corporate email with your @yourdomain.com
  • Teams: video conferencing, chat, calls and real-time collaboration
  • SharePoint: corporate intranet and document management
  • OneDrive: personal cloud storage (1TB per user)
  • Word, Excel, PowerPoint: always up-to-date Office applications
  • Exchange Online: professional mailboxes with advanced protection
  • Entra ID (Azure AD): identity and secure access management
🛡️ Business Standard and Premium plans also include Defender for Business, an advanced cybersecurity solution.

The main business plans are:

  • Business Basic ($6/user/month): Teams, Exchange, SharePoint, OneDrive — web/mobile Office versions.
  • Business Standard ($12.50/user/month): everything above plus installable desktop Office apps.
  • Business Premium ($22/user/month): everything above plus advanced security (Defender, Intune, Azure AD Premium).
  • Apps for Business ($8.25/user/month): Office apps only, without email services.

ECSG helps you choose the right plan based on each user's profile and your company's budget.

MFA (Multi-Factor Authentication) is a security method that requires two or more forms of verification to access an account — in addition to the password, a second factor is required such as a code sent to the phone or an authenticator app.

It is critical because 99.9% of account compromise attacks are blocked when MFA is enabled, according to Microsoft data. A password alone is no longer sufficient protection.

🛡️ ECSG configures MFA for all Microsoft 365 users as a standard part of any implementation.

ECSG performs zero-downtime email migrations to Microsoft 365. The process includes:

  1. Audit of the current email system (Gmail, cPanel, Exchange on-premise, etc.)
  2. Microsoft 365 tenant setup and domain verification
  3. Migration of all mailboxes, contacts and calendars
  4. DNS record configuration (MX, SPF, DKIM, DMARC)
  5. Team training on the new environment
🕐 A typical migration for a 10–50 user company takes between 2 and 5 business days.

SharePoint is Microsoft 365's content management and collaboration platform. It acts as your company's corporate intranet, allowing you to centralize documents, policies, announcements and resources in a single place accessible to the entire team.

Key benefits: elimination of duplicate document versions, department-level access control, automated approval workflows, integration with Teams and Office, and access from any device.

Exchange Online is the corporate email service of Microsoft 365. Unlike free services (Gmail, Hotmail), Exchange Online offers:

  • Custom corporate domain (@yourdomain.com)
  • 50 GB of storage per mailbox
  • Advanced anti-spam and anti-phishing protection
  • eDiscovery and legal email retention
  • 99.9% availability guaranteed by SLA
  • Compliance with regulations (HIPAA, GDPR, ISO 27001)

Microsoft Intune is the Mobile Device Management (MDM) and Mobile Application Management (MAM) solution included in Microsoft 365 Business Premium and Enterprise plans.

It allows IT administrators to: control which devices access corporate data, enforce security policies on smartphones, tablets and PCs, remotely wipe lost or stolen devices, and manage corporate applications centrally.

Every Microsoft 365 implementation with ECSG includes personalized training for the team: training sessions on Teams, Outlook, SharePoint and OneDrive; user guides tailored to your company's processes; bilingual documentation; and post-implementation support for team questions.

We also offer continuous adoption programs and advanced training as additional services.

Yes. Microsoft 365 stores U.S. tenant data in Microsoft's U.S.-based data center regions and complies with major frameworks used by American businesses, including HIPAA, PCI DSS, SOC 2, ISO 27001 and FedRAMP (for eligible government workloads).

ECSG configures Microsoft 365 tenants specifically for U.S. compliance needs — setting the correct data residency region, retention policies and audit logging so your company meets the regulatory requirements of your industry.

☁️

Azure Cloud

Infrastructure, servers, backup and cloud services

Microsoft Azure is Microsoft's cloud computing platform, one of the largest in the world alongside AWS and Google Cloud. It offers over 200 cloud services that allow businesses to build, deploy and manage applications and technology infrastructure without needing physical servers of their own.

With Azure, your company can have virtual servers, databases, networking, storage, security and data analytics available globally, paying only for what you use.

These are the three main cloud service models:

  • IaaS (Infrastructure as a Service): virtualized infrastructure — servers, networking, storage. You manage the OS and above. Example: Azure Virtual Machines.
  • PaaS (Platform as a Service): platform for developing and deploying apps without managing underlying infrastructure. Example: Azure App Service, Azure SQL Database.
  • SaaS (Software as a Service): ready-to-use software, accessible via internet. You simply use the app. Example: Microsoft 365, Salesforce.
ℹ️ ECSG implements all three models based on each client's needs.

Azure Backup is Microsoft's cloud backup service that protects data from servers, VMs, databases, files and workloads (SQL Server, SAP HANA, etc.).

It is critical because it guarantees disaster recovery from ransomware, hardware failure, accidental deletion or natural disasters. Backups are stored AES-256 encrypted in geographically distributed data centers.

⚠️ 3-2-1 Rule: 3 copies of data, on 2 different storage types, with 1 offsite copy. Azure Backup makes this automatic.

Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud identity and access management service. It acts as your company's "central directory" in the cloud.

It enables: Single Sign-On (SSO) for all Microsoft 365 and third-party apps, centralized user and group management, conditional access policies, and multi-factor authentication (MFA). It is the security foundation of the entire Microsoft ecosystem.

Azure Firewall is a managed cloud network security service that protects Azure resources from external threats. Unlike traditional physical firewalls, it is fully scalable with no hardware required.

It includes: rule-based network traffic filtering, Microsoft threat intelligence, TLS traffic inspection, integrated high availability and complete audit logs.

An Azure Virtual Network (VNet) is an isolated private network within Microsoft's infrastructure. It allows your Azure resources (VMs, databases, etc.) to communicate with each other securely, as if they were on a private corporate network.

It can be connected to your on-premise network via Site-to-Site VPN or ExpressRoute, creating a secure hybrid infrastructure.

Azure Monitor is Microsoft Azure's centralized monitoring and observability solution. It collects, analyzes and acts on telemetry from your cloud and on-premise resources.

It enables automatic alerts, real-time dashboards, anomaly detection and log analysis. ECSG configures Azure Monitor as part of the Managed IT service to detect and resolve issues before they affect your operations.

Azure DevOps is a set of services for managing the software development lifecycle (ALM). It includes: project boards (Boards), code repositories (Repos), CI/CD pipelines to automate deployments, automated testing and artifact management.

🛡️

Cybersecurity

Protection, threats, compliance and best practices

Ransomware is a type of malware that encrypts the victim's files and demands a ransom to unlock them. It is one of the most devastating attacks for businesses — 60% of SMBs that suffer one close within 6 months.

To protect against it, ECSG implements a layered defense strategy built on our cybersecurity stack:

  • Immutable, automated backups with Datto BCDR and Azure Backup — the most effective antidote against ransomware
  • AI-driven endpoint protection (EDR) with SentinelOne, which can autonomously detect and roll back ransomware in seconds
  • Email threat protection with Proofpoint to stop malicious attachments and links before they reach the inbox
  • Ongoing phishing simulations and security awareness training with BullPhish ID
  • 24/7 threat monitoring through our RocketCyber Managed SOC
  • Network segmentation to limit lateral movement

Phishing is a social engineering attack where cybercriminals impersonate legitimate entities (banks, Microsoft, well-known companies) to trick users into giving up credentials, financial information or installing malware.

Red flags of a phishing email:

  • Sender domain different from the official one (e.g.: microsoft-support.net instead of microsoft.com)
  • Artificial urgency: "your account will be blocked in 24 hours"
  • Spelling or grammar errors
  • Links that show different URLs when you hover over them
  • Requests for credentials or financial data via email
💡 ECSG deploys BullPhish ID for simulated phishing campaigns and ongoing Security Awareness Training, backed by Proofpoint email filtering, so your team learns to spot real threats before they cause damage.

A firewall is a network security system (hardware, software or cloud) that monitors and controls incoming and outgoing network traffic according to predefined security rules. It acts as the first line of defense for your corporate network.

Modern firewalls (NGFW — Next-Generation Firewall) go beyond basic filtering: they inspect packet content (DPI), identify applications, detect intrusions (IPS), filter URLs and apply advanced security policies.

An NGFW (Next-Generation Firewall) is an evolution of the traditional firewall that incorporates advanced security capabilities:

  • Deep Packet Inspection (DPI): deep inspection of traffic content
  • Application Awareness: identification and control by application (not just port)
  • Intrusion Prevention System (IPS): real-time detection and blocking of exploits
  • SSL/TLS Inspection: decryption and inspection of encrypted traffic
  • Threat Intelligence: integration with global threat intelligence feeds
  • User Identity: user-based policies, not just IP

Leading brands: Fortinet FortiGate, Palo Alto Networks, Cisco Firepower, Sophos XGS.

Zero Trust is a security model based on the principle of "never trust, always verify." Unlike the traditional model that trusted everything inside the corporate network, Zero Trust assumes no user, device or application is trusted by default — even if inside the network.

The pillars of Zero Trust are: continuous identity verification (MFA), least privilege access, micro-network segmentation, continuous monitoring of all activities and encryption of all data in transit and at rest. ECSG implements Zero Trust using Microsoft 365 and Azure tools.

DLP (Data Loss Prevention) is a set of policies and technologies that prevent sensitive information from leaving the organization without authorization — whether by mistake, negligence or malicious intent.

Microsoft 365 includes built-in DLP that can detect credit card numbers, social security numbers, medical data and other sensitive information in emails, documents and Teams messages, and automatically block their unauthorized transmission.

A pentest (Penetration Test) is an ethical and controlled attack on an organization's systems to identify vulnerabilities before real attackers exploit them. A pentest evaluates: internal and perimeter network security, web application vulnerabilities, configuration security and personnel resistance to social engineering attacks.

SIEM (Security Information and Event Management) is a platform that centralizes, correlates and analyzes security logs and events from the entire IT infrastructure in real time to detect threats and respond to incidents. Microsoft offers Microsoft Sentinel, a cloud-native SIEM that uses artificial intelligence to detect attack patterns and automate responses.

ECSG helps organizations comply with multiple security standards and regulations:

  • ISO/IEC 27001: international information security management standard
  • NIST Cybersecurity Framework: U.S. government cybersecurity framework
  • HIPAA: health information protection in the U.S.
  • GDPR: European personal data protection regulation
  • PCI DSS: payment card data security standard

ECSG protects clients using a curated, enterprise-grade cybersecurity stack — the same class of tools used by large enterprises, sized and priced for SMBs:

  • Kaseya VSA: unified RMM platform for endpoint monitoring, patching and remote management
  • SentinelOne: AI-powered EDR/XDR for autonomous endpoint threat detection and ransomware rollback
  • DefensX: browser and web-layer security that blocks malicious sites, downloads and DNS-based threats before they reach the endpoint
  • Proofpoint: advanced email security — anti-phishing, anti-malware and business email compromise (BEC) protection
  • Datto: business continuity and disaster recovery (BCDR) with immutable, ransomware-resistant backups
  • RocketCyber: Managed SOC / MDR service providing 24/7 threat monitoring and incident response
  • BullPhish ID: phishing simulation and security awareness training platform
🛡️ These tools work together as a single layered defense — not isolated point products — so threats are caught at multiple stages: the browser, the inbox, the endpoint and the network.

EDR (Endpoint Detection and Response) continuously monitors laptops, desktops and servers for suspicious behavior, going far beyond traditional signature-based antivirus. XDR (Extended Detection and Response) correlates that endpoint data with signals from email, network and cloud sources for a fuller picture of an attack.

ECSG deploys SentinelOne across all managed endpoints. Its AI engine detects malicious behavior in real time and can automatically isolate an infected device and roll back files to their pre-attack state — often stopping ransomware before it spreads, with no manual intervention required.

A SOC (Security Operations Center) is a team and platform that watches your environment around the clock for signs of compromise. MDR (Managed Detection and Response) is the service model where that monitoring, investigation and response is delivered to you as a managed service, rather than built in-house.

ECSG partners with RocketCyber to provide 24/7 Managed SOC / MDR coverage — analysts review alerts around the clock, filter out noise and escalate only real threats, so your team isn't buried in false positives but is alerted immediately when something needs action.

Business Email Compromise (BEC) is a targeted attack where criminals impersonate an executive or vendor to trick employees into wiring money or sharing sensitive data — one of the costliest cybercrime categories for U.S. businesses.

ECSG layers Proofpoint email security (advanced anti-phishing, anti-malware, impersonation and BEC detection) with DefensX web/browser protection and recurring BullPhish ID phishing simulations, so threats are blocked technically and your team is trained to recognize what slips through.

🖥️

Managed IT (MSP)

Technical support, monitoring and infrastructure management

An MSP (Managed Service Provider) is a company that proactively manages the IT infrastructure, systems and applications of its clients under a service contract. Unlike reactive IT support (break-fix), the MSP continuously monitors, maintains and optimizes your technology before problems impact your operations.

ECSG operates as a full MSP: it manages your Microsoft 365, Azure, security, networks, backups and devices, acting as your company's external IT department.

ECSG's Managed IT service includes:

  • Proactive 24/7 infrastructure monitoring and automatic alerts
  • OS and software patch and update management
  • Backup management and recovery verification
  • Helpdesk technical support (Level 1, 2 and 3)
  • Microsoft 365 and Azure license management
  • User, group and permissions administration
  • Monthly infrastructure status reports
  • Capacity planning and strategic recommendations
  • Level 1 (L1): first contact, basic issues (password reset, connectivity issues, email setup). Quick resolution or escalation.
  • Level 2 (L2): specialized technicians resolving more complex issues (network configuration, server issues, advanced diagnosis).
  • Level 3 (L3): senior engineers handling critical issues, architecture changes, complex integrations and escalations requiring coordination with vendors.

ECSG provides support at all three levels for clients with a Managed IT contract.

Active Directory (AD) is Microsoft's directory service that manages identities and resources on a corporate network. It is the central authentication and authorization system: it controls who can log in, what resources each user can access and what security policies apply to devices.

A BCP (Business Continuity Plan) is a strategic document that describes how an organization will continue operating during and after an unplanned disruption (system failure, natural disaster, cyberattack, pandemic). It includes the DRP (Disaster Recovery Plan), which details how to recover IT systems. Key metrics: RTO (Recovery Time Objective) and RPO (Recovery Point Objective).

🛡️ ECSG designs and implements BCP/DRP plans using Datto BCDR appliances alongside Azure Site Recovery and Azure Backup as the technology base.

RMM is the technology that allows MSPs to remotely monitor and manage their clients' devices and systems. ECSG runs Kaseya VSA as its core RMM platform, which lets us: see the health status of all your equipment in real time, detect issues before they fail, install patches and updates remotely, resolve incidents without on-site visits and generate automatic inventory and performance reports — all from a single pane of glass.

Virtualization allows running multiple operating systems (virtual machines) on a single physical server, making better use of hardware resources. Technologies like Hyper-V (Microsoft) or VMware vSphere are the most widely used platforms. Benefits: reduced hardware costs, greater flexibility, snapshots for backup and quick recovery, and the foundation for cloud migration.

👑

vCIO Consulting

Technology strategy and IT leadership for your business

A vCIO (Virtual Chief Information Officer) is an external technology director who acts as the CIO (IT Director) of a company without needing to hire a full-time executive. It is the ideal service for SMBs that need strategic technology leadership but cannot justify the cost of an internal CIO.

ECSG's vCIO becomes your trusted technology advisor: aligning technology with business objectives, planning IT investments, managing vendors and advising on strategic decisions.

ECSG's vCIO performs:

  • Periodic strategic IT review meetings (monthly/quarterly)
  • 1, 2 and 3-year technology roadmap aligned with business goals
  • Evaluation and recommendation of technology investments
  • Vendor relationship management and contract negotiation
  • Technology risk assessment and continuity planning
  • Regulatory compliance and security advisory
  • Cost-benefit analysis of technology projects

A technology roadmap is a strategic plan that defines what technologies to implement, when and why, aligned with the company's growth objectives. It establishes investment priorities, implementation milestones and success metrics. ECSG's vCIO designs your company's technology roadmap to ensure each IT investment generates measurable business value.

Digital transformation is the process of integrating digital technology into all areas of a business, fundamentally changing how it operates and delivers value to its customers. It is not just about adopting new technology — it is about redesigning processes, culture and business models with technology as the enabler.

Technology ROI (Return on Investment) measures the financial return on IT investments. To calculate it: (Benefit obtained – Investment cost) / Investment cost × 100. Technology benefits include: operational cost reduction (typically 40% with ECSG), productivity increases, reduced downtime losses, avoiding security incident costs and enabling new revenue.

🌐

Networking, Cabling & Standards

Network infrastructure, switches, firewall and standards

Structured cabling is a standardized telecommunications cabling system that supports multiple services (voice, data, video) within a building or campus. Unlike ad-hoc cabling, structured cabling follows international standards that guarantee performance, scalability and ease of maintenance.

📜 ECSG installs certified structured cabling under ANSI/TIA-568 and ISO/IEC 11801 standards.

Ethernet cable categories differ in supported speed and distance:

  • Cat5e: up to 1 Gbps at 100m. Standard for basic office networks. Still functional but limited for modern environments.
  • Cat6: up to 1 Gbps (10 Gbps at 55m). Better shielding, less crosstalk. Currently the recommended standard.
  • Cat6A: up to 10 Gbps at 100m. Ideal for data centers, hospitals and environments requiring maximum performance and future scalability.
  • Cat7/Cat8: up to 25-40 Gbps. Used in high-density data centers.

ECSG recommends installing a minimum of Cat6 in new installations to ensure compatibility with future technologies.

A switch is a network device that connects multiple devices within the same network (LAN) and intelligently directs data traffic to the correct destination. Types of switches:

  • Unmanaged: plug-and-play, no configuration. For small simple networks.
  • Managed: configurable with VLANs, QoS, STP, SNMP. For enterprise environments.
  • Layer 2: operate at MAC address level. Basic switching.
  • Layer 3: include routing capabilities between VLANs. Reduce the need for a dedicated router.
  • PoE (Power over Ethernet): supply electrical power via the network cable (ideal for IP cameras, VoIP phones and Wi-Fi APs).

A VLAN (Virtual Local Area Network) is a logical segmentation of the network that allows creating separate virtual networks within the same physical infrastructure. Devices on different VLANs cannot communicate with each other without passing through a router or firewall.

Common use cases: separating employee networks from guest Wi-Fi, isolating security systems (cameras, access control), separating servers from workstations and meeting PCI DSS and ISO 27001 segmentation requirements.

The main international structured cabling standards are:

  • ANSI/TIA-568: U.S. standard for commercial building telecommunications cabling. Defines cable types, connectors, maximum distances and installation procedures.
  • ISO/IEC 11801: equivalent international standard, adopted in Europe and Latin America.
  • ANSI/TIA-569: standards for telecommunications pathways and spaces (raceways, conduits, data rooms).
  • ANSI/TIA-606: administration and identification standard for structured cabling.
  • ANSI/TIA-607: grounding and bonding requirements for telecommunications.
✅ ECSG installs and certifies cabling under these standards, delivering certification reports with a network analyzer.

PoE (Power over Ethernet) is a technology that allows transmitting electrical power through the network cable along with data, eliminating the need for separate power supplies for end devices. Standards: IEEE 802.3af (15.4W), IEEE 802.3at/PoE+ (30W), IEEE 802.3bt/PoE++ (60-90W). PoE-powered devices: IP cameras, VoIP phones, Wi-Fi access points, IoT sensors and access control readers.

SD-WAN (Software-Defined Wide Area Network) is a technology that intelligently virtualizes and manages WAN connections (internet, MPLS, LTE) for a multi-site company. It enables prioritizing critical traffic, automatic failover between connections and cost reduction compared to traditional MPLS.

A VPN (Virtual Private Network) creates an encrypted communication tunnel over the internet, allowing secure access to corporate resources as if you were physically in the office. Main types:

  • Remote Access VPN: for remote employees accessing the corporate network from home or travel.
  • Site-to-Site VPN: permanently and securely connects two offices over the internet.
  • SSL VPN / ZTNA: remote access without a traditional VPN client, based on Zero Trust.

A rack (or telecommunications cabinet) is the standard 19" structure that organizes and houses network equipment, servers and telecommunications systems. Its capacity is measured in rack units (U), where 1U = 44.45mm in height. A well-organized data room includes: rack with cable management, labeled patch panel, switches, firewall, UPS (power backup), adequate thermal management and controlled access. ECSG designs and installs data rooms following the TIA-942 standard.

📷

Cameras & Physical Security

Video surveillance, NVR, CCTV and remote access

ECSG installs professional video surveillance systems for businesses and institutions:

  • IP cameras (PoE): connected directly to the LAN, PoE-powered, recording to NVR. High resolution (4K/2K), remote access and AI video analytics.
  • Outdoor cameras: weather-resistant (IP66/IP67), night vision (IR or full-color), for perimeters, parking lots and access points.
  • PTZ cameras: motorized pan, tilt and zoom. Ideal for large areas like warehouses and lobbies.
  • Fisheye cameras: 360° fish-eye view. One camera covering a complete area.
  • Indoor cameras: discrete dome for offices, server rooms and points of sale.
ℹ️ Brands we work with: Hikvision, Dahua, Axis, Hanwha (Samsung), Uniview.

Analog CCTV (DVR): uses coaxial cable to transmit analog video signal to a DVR (Digital Video Recorder). More limited resolutions (up to 5MP in TVI/AHD), separate network cabling, less flexibility for remote access and scalability.

IP (NVR): uses network cable (Cat6) to transmit digitized video to an NVR (Network Video Recorder). Superior resolutions (4K, 8MP), integration with corporate network, native remote access, AI analytics and greater scalability. ECSG recommends and designs IP systems for new installations.

An NVR (Network Video Recorder) is the central device that receives, records and manages video from IP cameras. It includes high-capacity hard drives (optimized for continuous recording) and Video Management Software (VMS). Storage needs depend on: number of cameras, recording resolution, frames per second (fps), retention period (days) and compression type (H.264, H.265, H.265+). H.265+ can reduce storage by up to 70% compared to H.264.

🧮 ECSG performs the storage calculation as part of system design. A typical 8-camera HD system with 30-day retention requires 2–4TB.

Yes. All IP systems installed by ECSG include remote access from any internet-connected device: smartphone (iOS/Android), tablet or computer. ECSG configures remote access securely — never exposing the NVR directly to the internet, but through the manufacturer's cloud services or VPN.

IVA (Intelligent Video Analytics) is the ability of modern cameras and NVRs to analyze video content in real time using artificial intelligence to detect specific events without human intervention. Available functions: perimeter intrusion detection, virtual line crossing, abandoned/removed object detection, people counting, license plate recognition (LPR), facial detection, behavior analytics and heat maps.

ECSG's complete camera installation service includes:

  1. Site survey: technical visit to evaluate the space, identify blind spots and design optimal coverage.
  2. System design: technical proposal with camera layout, equipment specifications and budget.
  3. Structured cabling: PoE Cat6 installation for each camera.
  4. Camera and NVR installation: mounting, image, resolution and recording configuration.
  5. Remote access setup: mobile and PC apps configured and tested.
  6. Training: staff training on operating the system.
  7. Acceptance certificate: document certifying the system operates to specification.

Camera resolutions determine image quality and the ability to identify people and details:

  • HD (1MP / 720p): 1280×720 px. Basic, sufficient for small areas.
  • Full HD (2MP / 1080p): 1920×1080 px. Current standard for most installations.
  • 2K (4MP): 2560×1440 px. More detail, ideal for access points and cash registers.
  • 4K (8MP): 3840×2160 px. Maximum quality, allows digital zoom without losing detail. Ideal for customs, banks and critical areas.

ECSG recommends a minimum of Full HD for new installations and 4K for high-importance areas.

📘

Technical Glossary

Key terms in cloud, networking, security and infrastructure

Cloud Computing
Delivery of computing services (servers, storage, databases, networking, software) over the internet with pay-per-use billing. Eliminates the need for physical infrastructure of your own.
Firewall
Network security system that monitors and controls incoming and outgoing traffic based on security rules. The first line of perimeter defense for any corporate network.
VPN
Virtual Private Network. Encrypted communications tunnel over the internet enabling secure access to private network resources from any location.
DNS
Domain Name System. Translates domain names (www.ecsgtech.com) into IP addresses that devices use to communicate. The "phone book" of the internet.
DHCP
Dynamic Host Configuration Protocol. Automatically assigns IP addresses and network parameters to connecting devices, eliminating manual IP configuration.
TCP/IP
Fundamental internet communication protocol suite. TCP guarantees ordered delivery of data packets; IP manages addressing and routing.
LAN / WAN
LAN (Local Area Network): local network within a building or office. WAN (Wide Area Network): wide-area network connecting multiple geographically distant sites, including the internet.
VLAN
Virtual LAN. Logical segmentation of a physical network into multiple isolated virtual networks. Improves security and performance by separating traffic by department or function.
SSL / TLS
Encryption protocols that secure internet communications. TLS is the modern version of SSL. The padlock in the browser bar indicates a TLS connection. Essential for email, web and VPN.
AES-256
Advanced Encryption Standard with 256-bit keys. Symmetric encryption algorithm considered the strongest security standard today. Used in Azure Backup, VPNs and secure communications.
MFA
Multi-Factor Authentication. Security method requiring two or more verification forms to access an account — password plus a second factor (phone code, authenticator app). Blocks 99.9% of account attacks.
SPF / DKIM / DMARC
DNS email authentication records that prevent domain spoofing/phishing. SPF defines authorized sending servers; DKIM digitally signs messages; DMARC defines what to do with failing messages.
QoS
Quality of Service. Mechanism that prioritizes certain types of network traffic (voice, video) over others to guarantee performance of critical applications, especially on congested networks.
PoE
Power over Ethernet. Standard enabling transmission of electrical power through Cat5e/Cat6 cable, powering IP cameras, VoIP phones and Wi-Fi APs without separate electrical wiring.
STP / RSTP
Spanning Tree Protocol. Network protocol preventing loops in networks with redundant switches, ensuring only one active path exists between two points. RSTP is the fast version (<1 second convergence).
SNMP
Simple Network Management Protocol. Standard protocol for monitoring and managing network devices (switches, routers, firewalls, servers). Enables RMM tools to collect metrics and generate alerts.
IPS / IDS
Intrusion Prevention/Detection System. IDS detects and alerts on malicious network activity. IPS goes further and automatically blocks detected attacks. Key component of modern NGFWs.
WAF
Web Application Firewall. Protects web applications by filtering and monitoring HTTP/HTTPS traffic against attacks like SQL injection, XSS and CSRF. Azure includes WAF built into Application Gateway.
RTO / RPO
Recovery Time Objective / Recovery Point Objective. RTO: maximum acceptable time to recover a system after failure. RPO: maximum acceptable data loss measured in time. Key metrics of any disaster recovery plan.
SOC
Security Operations Center. Operations center that monitors, detects, investigates and responds to cybersecurity incidents in real time, 24/7/365. ECSG can integrate SOC capabilities for clients that require it.
ONVIF
Open Network Video Interface Forum. Interoperability standard for IP cameras and video surveillance systems. Guarantees cameras from different manufacturers are compatible with the NVR. All ECSG-installed systems are ONVIF compliant.
H.265 / HEVC
High Efficiency Video Coding. Video compression standard that reduces recording file sizes by up to 50% compared to H.264, maintaining the same image quality. Essential for optimizing storage in camera systems.
IP66 / IP67
Environmental protection rating for electronic equipment. IP66: resistant to powerful water jets (outdoor cameras). IP67: resistant to 1-meter immersion for 30 minutes. Standard for outdoor cameras exposed to rain and dust.
TIA-568
ANSI/TIA standard defining structured cabling requirements for commercial buildings in the U.S.: cable types, connectors, maximum distances, pin configurations and required certification tests.
IEEE 802.11
Wi-Fi standards family from the IEEE. 802.11n (Wi-Fi 4), 802.11ac (Wi-Fi 5, up to 3.5 Gbps), 802.11ax (Wi-Fi 6, up to 9.6 Gbps, efficiency in high user density environments).
IEEE 802.3
Ethernet (wired network) standard. Defines physical and data link specifications for wired LAN networks: speeds (100M, 1G, 10G), cable types (Cat5e, Cat6, fiber optic) and PoE (802.3af/at/bt).
SFP / SFP+
Small Form-factor Pluggable. Hot-swappable transceiver modules for switches and routers. SFP: up to 1 Gbps. SFP+: up to 10 Gbps. Enable fiber optic connectivity for high-speed inter-switch links.
OSI Model
Open Systems Interconnection. 7-layer reference model for understanding network communications: Physical, Data Link, Network, Transport, Session, Presentation, Application. Fundamental for network troubleshooting and architecture design.
HA / Failover
High Availability / Failover. System architecture designed to maintain service continuity against component failures. When a primary system fails, the secondary automatically takes over, minimizing downtime.
CDN
Content Delivery Network. Globally distributed server network delivering web content from the server closest to the user, reducing latency and improving performance. Azure CDN and Cloudflare are popular examples.
API
Application Programming Interface. Set of rules and protocols allowing different applications to communicate with each other. Microsoft Graph REST APIs enable integrating Microsoft 365 with custom business applications.
CIDR
Classless Inter-Domain Routing. Notation for describing IP address ranges and subnet masks. Example: 192.168.1.0/24 indicates 256 possible addresses. Foundation of any corporate network design.
MDM
Mobile Device Management. Solution for managing and securing corporate or BYOD mobile devices (smartphones, tablets). Microsoft Intune is Microsoft 365's MDM solution. Enables policy enforcement, encryption and remote wipe.
SD-WAN
Software-Defined Wide Area Network. Technology that intelligently manages WAN connections across multiple sites. Enables traffic prioritization, automatic failover and cost reduction vs. traditional MPLS.
Zero Trust
"Never trust, always verify" security model. Assumes no user, device or application is trusted by default, even if inside the corporate network. Based on MFA, least privilege, micro-segmentation and continuous monitoring.
EDR / XDR
Endpoint / Extended Detection and Response. AI-driven security that monitors device behavior in real time to detect and automatically stop advanced threats like ransomware. ECSG deploys SentinelOne across all managed endpoints.
MDR / SOC
Managed Detection and Response / Security Operations Center. Outsourced 24/7 threat monitoring and incident response service. ECSG delivers MDR through its RocketCyber-powered Managed SOC.
RMM
Remote Monitoring and Management. Platform that lets an MSP monitor, patch and manage client devices remotely. ECSG uses Kaseya VSA as its core RMM platform for Managed IT clients.

Still Have Questions?

Our team is available to resolve any technical question — no commitment, real answers.

26 Belden Ave, Norwalk, CT  ·  info@ecsgtech.com  ·  www.ecsgtech.com